Hi Splunkies,
is there a way to set up log event event queuing and the chunking of queued events on the forwarder side?
Our problem is that our forwarders flood our indexer with events when it is back online after an outage due to maintenance or other reasons and some of those events are not indexed and get lost.
The fowarders are configured to use acknowledgement and SSL to encrypt the traffic between forwarders and indexers. The use of SSL and acknowledgement is required by the orgranizations data management and securicy policies.
Utilization on the indexer is quite low. CPU ist always <10% even after bringing them up online after maintainance.
Any suggestions or ideas, like a configuration to send queued events in chunks of like 10 Mb and how to do that?
René
... View more